ME

Security Engineer Internship

Hiring from
Worldwide
Work type
Remote
Posted
Sep 24, 2026
Is this job info correct?

Security Engineer

Overview: Supply Chain Security and Compliance

The Security Engineer is a critical role responsible for implementing and enforcing robust security practices across our entire integrated supply chain e-commerce platform. You will safeguard e-commerce transactions, secure internal tool integrations, and establish the trust framework for our AI agent operations, ensuring compliance with global regulatory standards like PCI-DSS and GDPR.

Internship Details

  • Duration: 3 months (extendable based on performance and project scope)

  • Start Date: Immediate

  • Location: Remote

  • Stipend: Unpaid initially; may convert to a paid internship, full-time role, or even direct client absorption (FTE) based on your performance

Key Responsibilities & Core Projects

You will secure all layers of the application, from the Next.js frontend to the NestJS modular monolith and the cloud infrastructure.

  • Security Architecture & Threat Modeling: Perform vulnerability assessments, code reviews, and threat modeling for all new features and systems, focusing on the critical MES $\rightarrow$ WMS $\rightarrow$ OMS business process flow.

  • Compliance Enforcement: Lead the implementation and auditing of security controls necessary for PCI-DSS compliance (for Payment module) and GDPR compliance (for user/tenant data handling).

  • Access Control & Authentication: Implement and manage secure API authentication methods, including OAuth 2.0 and SAML, utilizing Authentik/Ory Kratos and leveraging PostgreSQL's Row-Level Security (RLS) for tenant isolation.

  • Secrets & Encryption: Manage secrets and key rotation using Vault, define and enforce encryption protocols for data both in transit and at rest, and manage certificates via Traefik.

  • Abuse Prevention: Implement and monitor controls for API rate limiting, Web Application Firewall (WAF) rules, and traffic monitoring to prevent abuse and denial-of-service attacks.

  • Incident Response: Develop and practice incident investigation and response protocols. Conduct security awareness training for development and operations teams.

Required Technologies & Tools

Candidates must possess hands-on security experience with our core stack and compliance tools:

  • Platform Security: Node.js/NestJS security best practices, Next.js/React security, PostgreSQL RLS.

  • Compliance Focus: Experience with PCI-DSS and GDPR controls and auditing.

  • Authentication & Access: OAuth 2.0, SAML, JWT, Authentik/Ory Kratos.

  • Secrets & Infrastructure: HashiCorp Vault, Docker, Terraform.

  • Monitoring & Assessment: Tools for Static/Dynamic Application Security Testing (SAST/DAST).

AI Agent Security

You will be responsible for securing the emerging AI ecosystem.

  • Agent Trust Framework: Establish security boundaries for the AI agent interfaces, ensuring agents (built with LangChain/AutoGen) operate within strict permissions when accessing supply chain data (WMS, OMS).

  • Prompt Injection Prevention: Implement validation and sanitization techniques to mitigate prompt injection and data exfiltration risks in user-facing LLM interactions.

Success Metrics & Career Path

Performance will be measured by:

  • Security Scorecard: Reduction in identified vulnerabilities from assessments and code reviews (SAST/DAST).

  • Compliance Audits: Successful passing of regular PCI-DSS and GDPR audits.

  • Incident Handling: Speed and effectiveness of security incident investigation and remediation.

Mentorship Structure: Reports to the Solution Architect or Head of Technology, working closely with the development and DevOps teams to embed security into the CI/CD pipeline.


Similar jobs

Apply for this job